<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-12118</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:45:03+09:00</news:publication_date>
      <news:title>CVE-2026-12118 IBM webMethods Integration Server の WmServiceMock による未認証RCE（パッチは無く、パッケージ削除が唯一の対処）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-66756</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:45:03+09:00</news:publication_date>
      <news:title>CVE-2026-66756 Apache Tika の tika-server で unpack エンドポイントが unsecureFeatures=false でも有効になる（4.0.0-beta-1 で修正）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-14529</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:45:03+09:00</news:publication_date>
      <news:title>CVE-2026-14529 IBM WebSphere Application Server の SIP コンテナ有効時に未認証SSRF（sipServlet-1.1 を使っている構成のみ該当）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-68979</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T18:29:16+09:00</news:publication_date>
      <news:title>CVE-2026-68979 Apache NiFi パラメータコンテキスト更新が参照コンポーネントの認可を検査しない（NVD 9.8 / Apache 判定は Medium）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-14537</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T18:29:16+09:00</news:publication_date>
      <news:title>CVE-2026-14537 Google mcp-toolbox のレガシー HTTP API 経由で scopeRequired の認可を回避できる（未認証・v1.5.0 で修正）</news:title>
    </news:news>
  </url>
</urlset>